logoalt Hacker News

gzreadlast Tuesday at 4:07 AM1 replyview on HN

You requested:

> real world compromises of major sites that don't use DNSSEC?

Without any other changes to this infrastructure DNSSEC by itself wouldn't have prevented this, but it could have been combined with something else like a CAA record.


Replies

akerl_last Tuesday at 8:20 AM

Sure. I guess by that logic this attack also could have been prevented by flossing, as long as you combined flossing with setting a CAA record.

show 1 reply